WordPress kk Star Ratings plugin <= 5.4.3 - Rate Manipulation due to IP Spoofing Vulnerability
CVE-2023-36528
5.3MEDIUM
Summary
A missing authorization vulnerability exists in the FeedbackWP kk Star Ratings plugin that allows attackers to exploit incorrectly configured access control security levels. This can potentially enable unauthorized users to manipulate ratings without proper authentication. The flaw affects several versions of the kk Star Ratings plugin, creating risks for WordPress site owners who fail to apply necessary security measures. Ensuring proper configuration and timely updates is essential to mitigate exposure to this vulnerability.
Affected Version(s)
kk Star Ratings <= 5.4.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)